Skip to content

CVE-2026-3276 on CTRL-OS 26.05

Aliases: CVE-2026-3276

Packages: python313

Status: Plausible, Resolved

Advisory Information

unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. This affects all normalization forms.

Updates

2026-07-23 16:02 CEST

Metadata changes:

  • Status for package python313: “Resolved” (fff38d56fb8e15a140da141149c596766b838d0b)

(Amended on: 2026-07-23 16:14 CEST)

2026-07-23 16:02 CEST

Metadata changes:

  • Status for package python314: “Resolved” (b907b8ba5e335b35aed7b8b2d2f2058d8f10e055)

(Amended on: 2026-07-23 16:14 CEST)

2026-07-23 16:02 CEST

Metadata changes:

  • Status for package python315: “Resolved” (597ad40f1206472be8823406acdf51bf24cb2899)

(Amended on: 2026-07-23 16:15 CEST)

2026-07-23 16:01 CEST

Metadata changes:

  • Status for package python311: “Plausible
  • Status for package python312: “Plausible
  • Status for package python313: “Plausible
  • Status for package python314: “Plausible
  • Status for package python315: “Plausible

2026-06-04 00:03 CEST

Metadata changes:

  • Status for package python311: “New
  • Status for package python312: “New
  • Status for package python313: “New
  • Status for package python314: “New
  • Status for package python315: “New

(Amended on: 2026-06-04 00:04 CEST)